Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be…
Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether th…
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized du…
Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect r…
By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the…
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13…
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, …
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1…
An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.…
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema…
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13…
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.3…
TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has histori…
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 …
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g.…
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c…
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…
TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to…
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o…
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstra…
TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms…
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two diff…
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone i…